NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
3214  CVE-2008-3333  Directory traversal vulnerability in core/lang_api.php in Mantis before 1.1.2 allows remote attackers to include and execute arbitrary files via the language parameter to the user preferences page (account_prefs_update.php).    7.5  High  2017-01-03  2009-03-17  View
3986  CVE-2008-4130  Cross-site scripting (XSS) vulnerability in Gallery 2.x before 2.2.6 allows remote attackers to inject arbitrary web script or HTML via a crafted Flash animation, related to the ability of the animation to "interact with the embedding page."    4.3  Medium  2017-01-03  2009-03-17  View
4003  CVE-2008-4147  Cross-site scripting (XSS) vulnerability in the Mailsave module 5.x before 5.x-3.3 and 6.x before 6.x-1.3, a module for Drupal, allows remote attackers to inject arbitrary web script or HTML via an e-mail message with an attached file that has a modified Content-Type.    4.3  Medium  2017-01-03  2009-03-17  View
4005  CVE-2008-4149  Cross-site scripting (XSS) vulnerability in the Greg Holsclaw Link to Us module 5.x before 5.x-1.1 for Drupal allows remote authenticated users to inject arbitrary web script or HTML via the "Link page header" field.    4.3  Medium  2017-01-03  2009-03-17  View
4006  CVE-2008-4150  SQL injection vulnerability in picture_category.php in Diesel Joke Site allows remote attackers to execute arbitrary SQL commands via the id parameter, a different vector than CVE-2006-3763.    7.5  High  2017-01-03  2009-03-17  View

Page 2859 of 17672, showing 5 records out of 88360 total, starting on record 14291, ending on 14295

Actions